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AMENDMENTS TO THE CLAIMS 

1 . (Currently Amended) A method for tracing content in a highly distributed 
system, comprising: 

receiving content associated with a content owner; 
decrypting the received content; 

determining a self-identifier that uniquely identifies an entity decrypting 

the content; 

modifying the decrypted content by embedding at least one of a 
fingerprint or a watermark into the decrypted content, wherein the fingerprint or 
watermark is generated, in part, from the self-identifier; 

encrypting the modified content; 

wrapping the encrypted modified content together with the self-identifier 
using an access key; 

associating a first s e t of information with th e d e crypt e d content, wher e in 
th e first s e t of information, in part, uniqu e ly identifies an e ntity decrypting th e cont e nt; 
and 

providing a s e cond set of information to the content owner, wherein the 
s e cond set of information enables the content owner to trace the content in the highly 
distributed system. 

2. (Currently Amended) The method of claim 1 , wherein decrypting the 
received content further comprises: 

obtaining [[an]] a different access key out-of-band, wherein the different 
access key is uniquely associated with the entity decrypting the content and a sender of 
the content; and 

employing the different access key to unwrap the received content before 
decrypting the received content . 
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3. (Currently Amended) The method of claim 1 , wherein the fingerprint or 
watermark is further generated based on another self-identifier that uniquely identifies a 
downstream market recipient of the content, associating th e first s e t of information 
furth e r compris e s: 

d e t e rmining a s e lf identifi e r a s sociat e d with the e ntity d e crypting th e 
cont e nt; 

det e rmining a fing e rprint bas e d, in part, on th e s e lf id e ntifi e r; and 
wat e rmarking th e d e crypted content e mploying th e fingerprint. 

4. (Currently Amended) The method of claim [[3]]I, wherein the self- 
identifier is digitally signed by an encryption key associated with the entity decrypting 
the content. 

5. (Currently Amended) The method of claim [[3]]1, wherein the self- 
identifier further comprises at least one of a serial number, and a time stamp indicating 
approximately when the content is decrypted. 

6. (Currently Amended) The method of claim 1, wherein the s e cond set of 
information further comprises at least one of traceability information, a time stamp, an 
identifier, and registration information associated with at least one of the content and the 
entity decrypting the content. 

7. (Currently Amended) The method of claim 1, further comprising: 
providing the wrapped encrypted modified content and self-identifier to a 

downstream market recipient; 

decrypting, by the downstream market recipient, the received modified 

content; 

further modifying the decrypted modified content by embedding another 
fingerprint or watermark into the modified content, wherein the other fingerprint or 
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watermark is generated in part from another self-identifier that uniquely identifies the 
downstream market recipient that decrypts the modified content; , 
encrypting the further modified content; and 

wrapping the encrypted further modified content together with the self- 
identifier that uniquely identifies the entity decrypting the content and the self-identifier 
that uniquely identifies the downstream market recipient, 

determining a s e lf id e ntifier associat e d with the e ntity d e crypting th e 

content; 

determining an acc e ss k e y associat e d with another r e cipient of the content 

and th e e ntity; 

encrypting th e content; 

wrapping th e e ncrypt e d content and th e s e lf id e ntifi e r employing the 

acc e ss key; 

forwarding th e wrapp e d and e ncrypt e d cont e nt to th e other r e cipi e nt, 

8. (Currently Amended) The method of claim [[ 7]]1_, wherein determining 
the access key further comprises receiving the access key employing an out-of-band 
mechanism. 

9. (Currently Amended) The method of claim [[ 7]]1_, wherein wrapping the 
encrypted modified content further comprises digitally signing the encrypted modified 
content. 

10. (Currently Amended) The method of claim [[ 7]]I, wherein the access key 
employs a public key infrastructure. 

1 1 . (Original) The method of claim 1, wherein the content is at least one of a 
subscription television, movies, interactive video games, video conferencing, audio, still 
images, text, graphics. 
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12. (Currently Amended) A security device for tracing content in a highly 
distributed system, comprising: 

a receiver configured to receive content associated with a content owner; 
a fingerprinter-watermarker configured to perform actions including: 

determining a self-identifier that uniquely identifies a recipient of 

the content; 

d e termining generating a fingerprint ba se d , in part-en from the 

self-identifier; and 

watermarking the content employing the fingerprint; and 
a forensics interface configured to send information associated with the 
watermarked content to the content owner. 

13. (Currently Amended) The security device of Claim 12, further comprising: 
a key wrap, coupled to the fingerprinter-watermarker, that is configured to 

perform actions, including: 

receiving an access key associated with the recipient of the 

content; and 

wrapping the content and together with the self-identifier 
employing the access key. 

14. (Original) The security device of claim 13, wherein the access key is 
received employing an out-of-band mechanism. 

15. (Original) The security device of claim 12, wherein the recipient is at least 
one of an aggregator, a service operator, and a user. 

16. (Original) The security device of claim 12, wherein the information 
associated with the watermarked content comprises at least one of traceability 
information, a time stamp, an identifier, and registration information associated with at 
least one of the content and the recipient of the content. 
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17. (Original) The security device of claim 12, further comprising: 
a data store configured to store decrypted content; and 

a fingerprinted-watermarked content data store configured to store 
encrypted content. 

1 8 . (Currently Amended) A network device for managing modulat e d data s ignal 
having computer e x e cutabl e instructions e mbodi e d th e reon for delivering content in a highly 
distributed system, th e modulated data s ignal comprising actions including : 

a transceiver that is arranged to receive and to send content to another 
network device; and 

at least one processor that is configured to execute program code to 
perform actions, including: 

receiving a first wrapper of content from a first market participant 
sent to a second market participant that is associated with the network device, the 
wrapper including encrypted content, a first identifier that uniquely identifies the first 
market participant, and a content key, wherein the encrypted content, content key, and 
unique first identifier are together encrypted into the first wrapper using an access key 
associated with the network device; 

decrypting the first wrapper using the access key; 

decrypting the encrypted content using the decrypted content key; 

generating at least one of a fingerprint or a watermark that 
uniquely identifies the second market participant; 

marking the decrypted content by embedding the fingerprint or 
watermark into the decrypted content; 

encrypting the marked content using the content key; 

generating a second wrapper that wraps together the content key, 

the encrypted marked content, the first unique identifier, and a second unique identifier 

that uniquely identifies the second market participant, using an access key associated 

with a third market participant; and 

transmitting the second wrapper to the third market participant. 
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transf e rring cont e nt from a mark e t participant to anoth e r mark e t 

participant; 

e nabling a d e cryption of th e cont e nt, if the transf e rr e d cont e nt is e ncrypt e d; 

e nabling an association of information with th e d e crypt e d cont e nt, wh e r e in th e 
information uniqu e ly identifi e s an e ntity associat e d with th e d e cryption of th e cont e nt; 

14-1 ivt 

providing th e information conc e rning th e d e crypt e d cont e nt to th e cont e nt 

own e r. 

1 9. (Currently Amended) The network device modulat e d data signal of claim 
18, wherein information associat e d with th e cont e nt furth e r comprises at l e ast on e of a 
fing e rprint, a wat e rmark, the second unique identifier further includes a time stamp that 
further indicates when the second wrapper is created , and a serial numb e r. 

20. (Currently Amended) An apparatus for tracing content in a highly 
distributed system, comprising: 

a means for receiving content associated with a content owner; 

a decryption means for decrypting the received content; 

means for determining an identifier that uniquely identifies the entity 
decrypting the content; 

means for modifying the decrypted content by embedding at least one of a 
fingerprint or watermark generated from the unique identifier into the decrypted content; 

means for wrapping the modified content; 

a m e ans for associating a first s e t of information with th e d e crypt e d 
cont e nt, wher e in th e first set of information, in part, uniqu e ly id e ntifi es an e ntity 
d e crypting th e cont e nt; 
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a means for determining a s e cond set of information associated with the 
decryption of the content; and 

a means for providing the second set of information to the content owner. 
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